Security researcher PaPPy, has submitted on 26/10/2010 a cross-site-scripting (XSS) vulnerability affecting ageconsearch.umn.edu, which at the time of submission ranked 3404 on the web according to Alexa.
We manually validated and published a mirror of this vulnerability on 20/12/2011. It is currently unfixed.
If you believe that this security issue has been corrected, please send us an e-mail. |
Date submitted: 26/10/2010 |
Date published: 20/12/2011 |
Fixed? Mail us! | Status: UNFIXED |
Author: PaPPy |
Domain: ageconsearch.umn.edu |
Category: XSS |
Pagerank: 3404 |
URL: http://ageconsearch.umn.edu/simple-search?sort=date&query='><script>alert(1);</script>&from_advanced =true&query2=&field1=keyword&conjunction2=AND&query1='><script>alert(1);</script>&field2=keyword&que ry3=&conjunction1=AND&field3=ANY&SortDirection=descending |
Click here to view the mirror
|
|
|